opendcim / openDCIM

An open source (GPL v3) Data Center Inventory Management (DCIM) application.
http://opendcim.org
305 stars 204 forks source link

23.04 - Users that have Admin Own Devices permissions to a certain group run reports that return all groups gear not just their own. #1527

Open cpbonamico opened 5 months ago

cpbonamico commented 5 months ago

Discussed in https://github.com/opendcim/openDCIM/discussions/1526

Originally posted by **cpbonamico** April 2, 2024 Has anyone seen this? We have DCIM locked down using DCIM permissions with groups. This works fine in DCIM. This user can only update and see gear that is assigned to their group. But when we try to run reports as this user, the reports button doesn't work. I looked at the PHP file and managed to get the reports.php file to load but all reports return all devices in the DC regardless of ownership.